PoE2 Oracle

Code signing policy

How PoE2 Oracle's releases are built, who approves them, and how you can check what you downloaded.

Not signed yet. PoE2 Oracle's installer and app don't carry a digital signature yet, so Windows may warn about them. PoE2 Oracle is seeking a signature from SignPath Foundation, which signs open-source projects for free; this page will say if it gets one. Until then, check your download against its checksums, as shown below.

How releases are built

  • Every release is built from the source code in the public repository github.com/mttzzz/poe2-oracle, by GitHub Actions on GitHub's own machines, when the maintainer tags a version. The workflow that does it, release.yml, is part of the repository: anyone can read how a release is made.
  • Nothing is carried over from earlier builds: there is no build cache, and the Rust compiler's version is fixed, so every release is compiled afresh from its tagged source.
  • Building, signing and publishing run as separate steps, and each key reaches only the step that uses it. A release first appears as a draft: the maintainer installs and tests it, then publishes it by hand.

Who approves

PoE2 Oracle has one maintainer, mttzzz, who holds all three roles:

  • Committers, who change the source code without a review: mttzzz.
  • Reviewers, who review every change someone else proposes, such as a pull request, before it's merged: mttzzz.
  • Approvers, who approve each release for signing: mttzzz.

He uses multi-factor authentication for GitHub, and will for SignPath.

How to check a download

Every release comes with two more files: SHA256SUMS, the installer's SHA-256 checksum, and SHA256SUMS.sig, an Ed25519 signature of that file made with PoE2 Oracle's release key. Only the release workflow can use the key, and the app carries its public half: before installing an update, the app checks both, and refuses an update that fails either check.

To check the installer you downloaded:

  1. Get the release's SHA256SUMS and SHA256SUMS.sig: from https://oracle.pushka.biz/download/v<version>/ while it is the latest release, or from its page on GitHub.
  2. In PowerShell, in the folder with the installer, run Get-FileHash .\PoE2-Oracle-Setup-<version>.exe. The hash must match the installer's line in SHA256SUMS; letter case doesn't matter.
  3. To check that the release key signed SHA256SUMS, run this in a copy of the source code, with Rust installed:
    cargo run -p release-sign -- verify SHA256SUMS SHA256SUMS.sig "$(cat crates/auto-update/release-signing-key.pub)"

More about it in the repository's security policy.

Privacy

PoE2 Oracle collects nothing about you or your play. It talks to the Path of Exile trade site, GGG's server of pictures and exchange data, poe2scout, and oracle.pushka.biz for updates. oracle.pushka.biz counts installations, starts and updates as anonymous numbers, with no address or id kept; a report reaches the developer only when you send one. The installer says so on its first page, where its Update automatically box turns updates, and with them the counting, off; the settings can switch them later. What goes where, in detail: the privacy policy; what is counted: What the service counts.

The services the app talks to have privacy policies of their own: Grinding Gear Games' for the trade site and GGG's server, and poe2scout's.